Chapter 3 of 6
Confirm these requirements:
- The approved subscription, resource group, regions, network pattern, tags, owners, and change record are recorded. The cloud platform owner confirms that they name the same approved scope.
- The deployment operator has time-bound Contributor on the exact approved sandbox resource group and time-bound Resource Policy Contributor on the approved subscription.
- The operator can run deployment what-if at resource-group and subscription scope.
- The cloud platform owner has reviewed inherited policy assignments and exemptions.
- The required Azure resource providers are registered.
Use team aliases and synthetic classifications in tags. Do not place credentials, resource IDs, endpoints, prompts, traces, responses, or customer data in parameters, tags, outputs, or source control.
Implementation files#
| Type | File | Consumer |
|---|---|---|
| Deployment | artifacts/infra/foundry/main.bicep | The platform deployment pipeline |
| Deployment | artifacts/infra/network/main.bicep | The platform deployment pipeline |
| Deployment | artifacts/environments/sandbox.bicepparam | The platform deployment pipeline |
| Deployment | artifacts/environments/network-foundation.bicepparam | The platform deployment pipeline |
| Deployment | artifacts/policy/initiative.bicep | The subscription policy deployment pipeline |
| Deployment | artifacts/policy/assignment.bicep | The sandbox policy deployment pipeline |
| Deployment | artifacts/policy/guardrail-settings.json | The initiative and assignment parameter builds |
| Deployment | artifacts/environments/initiative.bicepparam | The subscription policy deployment pipeline |
| Deployment | artifacts/environments/policy-assignment.bicepparam | The sandbox policy deployment pipeline |